Try our new research platform with insights from 80,000+ expert users

RSA Archer vs Tenable Lumin comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

RSA Archer
Ranking in IT Vendor Risk Management
4th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
42
Ranking in other categories
GRC (1st), IT Governance (1st)
Tenable Lumin
Ranking in IT Vendor Risk Management
19th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
3
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of February 2026, in the IT Vendor Risk Management category, the mindshare of RSA Archer is 6.9%, down from 11.2% compared to the previous year. The mindshare of Tenable Lumin is 1.9%, up from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
IT Vendor Risk Management Market Share Distribution
ProductMarket Share (%)
RSA Archer6.9%
Tenable Lumin1.9%
Other91.2%
IT Vendor Risk Management
 

Featured Reviews

CJ
Information Security Specialist at Dubai Health Authority
Centralized management strengthens compliance with good look and feel
From my perspective as a customer and end user, Archer has an impressive look and feel, but the most adaptive feature is its ease of configuration which helps to enhance our process according to our maturity. It's more about our organization getting centralized with an integrated approach that focuses on risk governance and compliance. When can provide a detailed dashboards to management with the details of risks from top-down or bottom-up prioritizing actions based on its criticality or necessity. This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
Yusuf-Hashmi - PeerSpot reviewer
Sr. Director - Group Head - IT Security (CISO) at Jubilant Organosys Ltd., India, Leading Chemical M
It creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks
Tenable Lumin's dashboard helps me understand my vulnerabilities and which tasks I should prioritize for vulnerability remediation. Tenable creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks. Real-time threat intelligence is also helpful. They get multiple sources of intelligence and correlate the data. Lumin discovers your assets through an agent or a network scan. That's an excellent feature that I'm leveraging now to better understand where all my assets are.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like how Archer requires very little programming ability. A person with minimum coding experience can configure the necessary fields in Archer. It's more of a drag-and-drop solution."
"Makes auditing much more convenient."
"One of the useful features is the ability to connect to various systems in order to accommodate data."
"The most valuable features of RSA Archer are the asset management, risk management, and vendor management."
"Archer has simplified our security audits. It's made it easier to raise and trigger questionnaires to customers."
"RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
"The integrated data model of a one-to-many/many-to-one relationship is quite useful."
"Flexible record permissions and data import features."
"Tenable Lumin is very good because it helps organizations look for solutions and profit. It also helps organizations save time because it displays market data well."
"The stability of this solution is appropriate. You can sleep well at night, if you have this solution implemented in your environment."
"Tenable Lumin's dashboard helps me understand my vulnerabilities and which tasks I should prioritize for vulnerability remediation. Tenable creates a risk score that helps me develop a remediation plan, so the infrastructure team can move quickly to address risks. Real-time threat intelligence is also helpful. They get multiple sources of intelligence and correlate the data. Lumin discovers your assets through an agent or a network scan. That's an excellent feature that I'm leveraging now to better understand where all my assets are."
 

Cons

"The user interface needs work. There are many small text boxes, like credit card size's boxes, where we need to input a lot of text. You can't see what you're typing beyond the tiny window, so you have to scroll or type elsewhere and copy-paste it. It's very inconvenient."
"I would like to see real-time data, from vulnerabilities, and threats."
"Recently, we made a suggestion for cross references, like for one application to another. There were limitations there, so we're hoping that will be included in the next upgrade."
"The technology's a little outdated."
"Some areas are not truly automated but are only scheduled."
"There is no inbuilt alert in Archer to let us know that a data feed has failed or did not run for different reasons. So, we don't even get to know that a feed has not run until somebody reports it to us. This has been a problem all the time. Data feeds have always been a big headache for us because there is no feature to let us know if a feed has not run or has failed. If Archer had a feature to send us an email notification when a feed has failed, it would've been very helpful. This is the reason why our users are slowly moving away to another platform. Some of the modules that I have been managing are being moved to ServiceNow. Next year, a lot of our modules will be moved from RSA Archer to ServiceNow, and the data feed issue has been one of the main reasons."
"It would be nice if RSA Archer featured more customization. When customers are updating, they should be notified whether certain updates are optional. The install screen should not proceed to the next page unless we make some selections about which updates we want to install."
"The ticket handling process could be improved."
"The solution's cloud operation has issues Lumin and Tenable are not one product. The integration needs to be worked out better. There is space for improvement there."
"The price could be better."
"Tenable Lumin isn't that old and still needs some time to mature."
 

Pricing and Cost Advice

"I am not 100% familiar with that, especially with their new model. I just know that the way they've licensed per user to scale is good."
"As I am a developer and responsible for providing production support, I do not have personal knowledge of the pricing. However, my colleagues claim that it is very expensive in comparison with other tools."
"The price of RSA Archer is good. The price isn't too high considering it is a leading tool in the market."
"The solution's price should be reduced. You only have to pay the license and there are no additional fees."
"The solution’s pricing is moderate."
"RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
"Fairly highly-priced, especially for smaller companies."
"The initial purchase is cheap. You pay a nominal price to start then renew the license annually. You also must buy a license for each module. I'm not too fond of that aspect of the licensing model. You buy the elephant and then spend more money to feed the elephant."
"The price could be better."
report
Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
883,011 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Insurance Company
12%
Manufacturing Company
7%
Government
5%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise6
Large Enterprise25
No data available
 

Questions from the Community

What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It would be helpful if RSA Archer had the capability for two-way integration because, i...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The specific module from ServiceNow is the ServiceNow Compliance, Risk, and Governan...
What advice do you have for others considering RSA Archer?
I have been in touch with about three companies who use RSA Archer actively in the compliance area. These companies use RSA Archer for nearly all purposes, including governance, internal risk, and ...
Ask a question
Earn 20 points
 

Comparisons

 

Also Known As

Archer
Lumin
 

Overview

 

Sample Customers

T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Information Not Available
Find out what your peers are saying about RSA Archer vs. Tenable Lumin and other solutions. Updated: February 2026.
883,011 professionals have used our research since 2012.